Our Services
Two Ways We Help
Whether you need a full adversarial simulation or a compliance scan for your cyber insurer, we have you covered.
External Penetration Testing
Full adversarial simulation
A full external penetration test simulates a motivated attacker targeting your organisation from the internet — no insider knowledge, no internal network access. Our testers use the same tools and techniques as real threat actors: OSINT-driven credential gathering, credential stuffing and spraying, and systematic attack surface enumeration.
We stop at the point of access, document exactly how we got in, and deliver a full written report with remediation steps and CVSS scores.
- Zero insider knowledge — black-box methodology
- OSINT-driven reconnaissance of public data
- Credential gathering from breached data sources
- Credential stuffing & account takeover attempts
- Attack surface inventory with risk ratings
- Full written report + executive summary + debrief
Vulnerability Scanning
Standalone — cyber insurance compliant
Not every organisation needs a full penetration test. Many cyber insurers only require a vulnerability scan as proof of regular security assessment — and a full pentest is often overkill for that requirement.
VSAT offers standalone vulnerability scans as a separate, cost-effective service. We scan your external-facing infrastructure for known CVEs and misconfigurations, and provide a formal report you can submit directly to your cyber insurer.
- Automated + validated scan of external infrastructure
- CVE identification with CVSS severity ratings
- Misconfiguration and exposure detection
- Formal written report accepted by major cyber insurers
- Faster turnaround than a full engagement
- Ideal for annual compliance cycles
VSAT now carries active Cyber Liability insurance. Our vulnerability scanning service is backed by real, compliance-aligned coverage — a credibility signal your cyber insurer can rely on, not a future intent.
Pentest Capabilities
What We Target
The following capabilities apply to our full external penetration testing service.
Credential Attacks
Password spraying, brute-force, credential stuffing against externally exposed login portals — Active Directory, SSO, email services, and SaaS platforms.
Credential Harvesting & Stuffing
OSINT-driven collection of leaked and exposed credentials, followed by systematic credential stuffing and password spraying against your externally accessible accounts and services.
External Attack Surface Mapping
Enumerate your public-facing infrastructure — subdomains, open ports, exposed APIs, and misconfigured services — to understand exactly what attackers can see.
Scope
What's In —
And What's Not
We operate strictly within the agreed external perimeter. We do not pivot from an external compromise into your internal network. Our focus is on the attack surface visible from the internet — this keeps the engagement scoped, safe, and highly relevant to real-world external threats.
Why It Matters
The Cost of Not Testing
External attack vectors are the primary entry point for modern breaches. Without regular testing, these risks remain invisible until it's too late.
Business Email Compromise
Attackers take over a single mailbox and impersonate executives to redirect wire transfers — average loss exceeds $130,000 per incident.
Ransomware Entry Points
83% of ransomware intrusions begin with a compromised external credential or exploited vulnerability. External testing closes that door before attackers open it.
Compliance Exposure
SOC 2, ISO 27001, and PCI-DSS all require evidence of regular penetration testing. A breach without documented tests means failed audits and regulatory fines.
Reputational Damage
Customer data breaches are public. The cost of a breach averages $4.45M, but the reputational hit often outlasts the recovery bill.
The average time to identify a breach is 194 days. By then, attackers have had over six months of undetected access to your systems, email, and customer data. External pen testing finds the door before they walk through it.
Our Process
From Kickoff to Report
Scoping Call
We define the target domains, IPs, and systems. Rules of engagement are documented and signed off before any testing begins.
Reconnaissance
Passive and active OSINT against your organisation — leaked credentials, exposed endpoints, email format discovery, and shadow IT inventory.
Attack Execution
Controlled execution of credential attacks, external vulnerability exploitation, and systematic attack surface testing against agreed targets.
Reporting & Debrief
Detailed written report with findings, CVSS scores, screenshots, and remediation steps. Live debrief call with your security team included.
Get Pricing
Request
Pricing.
Tell us what you need — full pentest or a standalone vulnerability scan for cyber insurance — and we'll reach out with a scoped proposal tailored to your environment.
Let's Talk Security
Reach out to the VSAT Security team directly and we'll get back to you within 24 business hours. Tell us about your environment and the engagement you have in mind.
Your email client will open with the subject and a short prompt — just add your company name and the services you're interested in, then hit send.
